PayloadSizeLayer class
LAYER 1 — Rejects oversized request payloads before any other work is done.
This is deliberately the first layer in the pipeline: it is the cheapest possible check (a single size measurement) and runs before signature verification, sanitization, or any other processing that would otherwise spend CPU on a payload that's going to be rejected anyway. This also blunts a class of denial-of-service attempts where an attacker sends huge bodies specifically to make expensive downstream work (HMAC computation, deep sanitization) costly.
- Implemented types
Constructors
- PayloadSizeLayer({SecurityConfig config = const SecurityConfig(), int? maxPayloadSize})
-
Creates a payload size layer, defaulting to
config'smaxPayloadSizeunlessmaxPayloadSizeis explicitly given.
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
- maxPayloadSize → int
-
Maximum accepted payload size, in bytes. Defaults to
SecurityConfig.maxPayloadSize (1 MB) unless overridden.
final
- name → String
-
A short, stable, human-readable name used in logs and results.
no setteroverride
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
Methods
-
check(
RequestContext context) → Future< SecurityResult> -
Inspects
contextand returns a SecurityResult.override -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited